git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git remote origin leaks user access token

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Jul 1, 2024, 16:27 UTC
Message-ID
<ZoLY_yxpQBjmp8O3@tapette.crustytoothpaste.net>
In-Reply-To
<ZoKW-yDJMsz9JPSI@google.com>
On 2024-07-01 at 11:46:03, Jonathan Nieder wrote:
Show 15 quoted lines
> (+cc: git@vger.kernel.org, git-security -> bcc)
> Hi!
> 
> limin wrote:
> 
> > Hi, I found a potential security issue when running a tool in my private
> > project. I think this exposes my personal access token to danger when using
> > "git remote get-url origin".
> 
> I'm moving this conversation to the public Git mailing list, as this
> behavior is well known.
> 
> I look forward to working together on ways to reduce the impact (for
> example, ways to encourage people to use their system's password
> keychain instead of including credentials in URLs).

I'll point out that we already document this in the Git FAQ (git help gitfaq):

---- How do I specify my credentials when pushing over HTTP?

The easiest way to do this is to use a credential helper via the `credential.helper` configuration. Most systems provide a standard choice to integrate with the system credential manager. For example, Git for Windows provides the `wincred` credential manager, macOS has the `osxkeychain` credential manager, and Unix systems with a standard desktop environment can use the `libsecret` credential manager. All of these store credentials in an encrypted store to keep your passwords or tokens secure.

In addition, you can use the `store` credential manager which stores in a file in your home directory, or the `cache` credential manager, which does not permanently store your credentials, but does prevent you from being prompted for them for a certain period of time.

You can also just enter your password when prompted. While it is possible to place the password (which must be percent-encoded) in the URL, this is not particularly secure and can lead to accidental exposure of credentials, so it is not recommended. ----

We also have a FAQ entry about how to read credentials from the environment as well, since that's a common thing people want to do.

I also recently added support for putting credentials that are not username and password (e.g., Bearer tokens) in credential helpers specifically for this purpose, since people were using `http.extraHeader` for this, which is equally insecure.

I do want to point out that several people, not just me, have worked together to make using a credential helper as easy and robust as possible. I mention this not to contradict Jonathan, who I think is also trying to help in this regard, but mostly to mention that as a project we've been trying to gently nudge people into doing the more secure thing. If people have further suggestions on how to make this easier for users in the future, I'm very eager to hear them.

-- 
brian m. carlson (they/them or he/him)
Toronto, Ontario, CA
Previous: Jonathan NiederNext: Jeff King
Message 2 of 6 in “Re: Git remote origin leaks user access token”
  1. Jonathan NiederJul 1, 2024
  2. brian m. carlsonJul 1, 2024
  3. Jeff KingJul 1, 2024
  4. H. Peter AnvinJul 2, 2024
  5. Jeff KingJul 2, 2024
  6. Junio C HamanoJul 1, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.